C.E. Niehoff
Disclosed Dec 23, 20214 years ago1,509 affectedConfirmed
C.E. Niehoff & Company, the covered entity (CE), reported that it experienced a cyberattack that compromised the protected health information (PHI) of 1,509 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, diagnoses, and medications. The CE notified HHS, affected individuals, the media, and provided substitute notice. In its mitigation efforts, the CE provided complimentary credit monitoring services and strengthened its administrative and technical safeguards to further safeguard PHI.
What is known
| People affected | 1,509 (as reported by the organization) |
|---|---|
| Disclosed | Dec 23, 2021 |
| Happened | Sep 9, 2021 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2021 data breach report: C.E. Niehoffin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): C.E. Niehoff (Health Plan, IL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Dec 23, 2021 | 16 |
| HHS archivetotal | Dec 23, 2021 | 1,509 |
History of this record
- 2026-09-25 · sector: other to insurance · backfill source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · summary: empty to C.E. Niehoff & Company, the covered entity (CE), reported that it experienced a cyberattack that compromised the protected health information (PHI) of 1,509 individuals. The PHI involved included names, addresses, dates of birth, Social Sec · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.